From b0c7472e0c0424b51f9871881f19e39e97b6a2af Mon Sep 17 00:00:00 2001 From: Abdallah Date: Wed, 22 Jul 2026 00:40:41 +0300 Subject: [PATCH] ci(release): make manual publish dispatch-only and add npm auth check Dedupe the two publish triggers so release-please.yml is the single automatic publisher (its inline jobs run on release_created). Convert publish.yml from an auto tag-push trigger to workflow_dispatch with a tag input, matching its documented emergency/recovery intent. Add an npm whoami fail-fast to both inline publish jobs so a bad token fails before building rather than mid-publish. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/publish.yml | 36 +++++++++++++++------------- .github/workflows/release-please.yml | 10 ++++++++ 2 files changed, 30 insertions(+), 16 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index d0e4496..bb0a66b 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,28 +1,31 @@ -# TAG-BASED RELEASE WORKFLOW (EMERGENCY USE ONLY) -# This workflow is triggered when git tags are pushed manually. +# MANUAL PUBLISH WORKFLOW (EMERGENCY / RECOVERY USE ONLY) +# This workflow is triggered manually from the Actions tab. # # ⚠️ IMPORTANT: For standard releases, just merge PRs to main. -# Release Please will automatically create release PRs and publish. +# Release Please creates the release PR, and on merge it tags and +# publishes via the publish jobs in release-please.yml. That is the +# single automatic publish path. # # Use this workflow ONLY for: # - Emergency hotfixes that bypass the normal flow -# - Manual re-publishing of failed releases +# - Manual re-publishing of a release that failed to publish # -# To use: -# git tag "@hive-academy/angular-3d@1.2.3" -# git push origin "@hive-academy/angular-3d@1.2.3" +# To use: Actions tab -> "Publish to NPM (Manual)" -> Run workflow -> +# enter the tag, e.g. @hive-academy/angular-3d@1.2.3 -name: Publish to NPM (Manual Tag) +name: Publish to NPM (Manual) on: - push: - tags: - - '@hive-academy/angular-3d@*' - - '@hive-academy/angular-gsap@*' - -# Issue 7 Fix: Concurrency control to prevent race conditions when multiple tags are pushed + workflow_dispatch: + inputs: + tag: + description: 'Existing tag to publish (e.g. @hive-academy/angular-3d@1.2.3)' + required: true + type: string + +# Concurrency control keyed on the requested tag concurrency: - group: publish-${{ github.ref }} + group: publish-${{ inputs.tag }} cancel-in-progress: false permissions: @@ -36,6 +39,7 @@ jobs: - name: Checkout code uses: actions/checkout@v4 with: + ref: ${{ inputs.tag }} # Check out the exact tag being published fetch-depth: 0 # Full history for changelog - name: Setup Node.js @@ -70,7 +74,7 @@ jobs: id: extract shell: bash run: | - TAG=${GITHUB_REF#refs/tags/} + TAG="${{ inputs.tag }}" PACKAGE_NAME=$(echo $TAG | sed 's/@[^@]*$//') VERSION=$(echo $TAG | sed 's/.*@//') echo "package_name=$PACKAGE_NAME" >> $GITHUB_OUTPUT diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 5eaf032..72fe4af 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -70,6 +70,11 @@ jobs: - name: Install dependencies run: npm ci + - name: Verify NPM authentication + run: npm whoami + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + - name: Build run: npx nx build angular-3d @@ -108,6 +113,11 @@ jobs: - name: Install dependencies run: npm ci + - name: Verify NPM authentication + run: npm whoami + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + - name: Build run: npx nx build angular-gsap